PT-2026-81356 · Pypi · Nltk
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NLTK versions prior to 3.10.3
Description
Insufficient validation of JVM options passed through the
options parameter in the java() function allows the injection of dangerous JVM flags. By supplying malicious options such as -agentpath, -javaagent, or @argfile to Stanford wrapper classes, an attacker can achieve arbitrary code execution.Recommendations
Update to version 3.10.3 or later.
As a temporary mitigation, restrict or avoid passing untrusted input to the
options parameter of the java() function.Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nltk